Fallos del tipo CWE-285

1609 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2026-1892LOWWeKan REST API boards.js setBoardOrgs improper authorizationEPSS 0.3%CVE-2025-65028MEDIUMRallly Has an IDOR Vulnerability in Vote Update Endpoint Allows Unauthorized Manipulation of Participant VotesEPSS 0.3%CVE-2026-32615MEDIUMDiscourse: Category group moderators can perform actions on topics in restricted categories without read accessEPSS 0.3%CVE-2025-71242MEDIUMSPIP < 4.3.6 Authorization Bypass Leading to Content DisclosureEPSS 0.3%CVE-2026-55236MEDIUMlanggraph-api: Incomplete assistant authorization in LangGraph Server run creationEPSS 0.3%CVE-2026-48810MEDIUMFreeScout: Thread Edit Authorization Bypass via Missing Mailbox CheckEPSS 0.3%CVE-2026-3237LOWIn affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiEPSS 0.3%CVE-2026-45147MEDIUMSiYuan: Broken access control in SiYuan `/api/tag/getTag` — Reader role can mutate `Conf.Tag.Sort` and persist to diskEPSS 0.3%CVE-2026-16279CRITICALImproper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026xEPSS 0.3%CVE-2026-47673MEDIUMHono: JWT middleware accepts any Authorization scheme, not only BearerEPSS 0.3%CVE-2024-23806MEDIUMHID Global Reader Configuration Cards Improper AuthorizationEPSS 0.3%CVE-2025-65031MEDIUMRallly Improper Authorization in Comment Endpoint Allows User ImpersonationEPSS 0.3%CVE-2026-34321MEDIUMVulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (comEPSS 0.3%CVE-2022-2393—A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication isEPSS 0.3%CVE-2025-6431MEDIUMThe prompt in Firefox for Android that asks before opening a link in an external application could be bypassedEPSS 0.3%CVE-2022-34405HIGHAn improper access control vulnerability was identified in the Realtek audio driver. A local authenticated malicious user may potentially exEPSS 0.3%CVE-2026-1894MEDIUMWeKan REST API checklistItems.js Checklist REST Bleed improper authorizationEPSS 0.3%CVE-2022-39873MEDIUMImproper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows physical attackers to add bookmarks in secret modEPSS 0.2%CVE-2023-0837MEDIUMAn improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Windows and macOS allowEPSS 0.2%CVE-2023-3899HIGHSubscription-manager: inadequate authorization of com.redhat.rhsm1 d-bus interface allows local users to modify configurationEPSS 0.2%